CVE-2025-8110
- EPSS 76.54%
- Veröffentlicht 10.12.2025 13:23:46
- Zuletzt bearbeitet 20.01.2026 13:47:34
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVE-2025-47943
- EPSS 0.3%
- Veröffentlicht 24.06.2025 03:48:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused b...
CVE-2024-56731
- EPSS 0.95%
- Veröffentlicht 24.06.2025 03:37:42
- Zuletzt bearbeitet 21.08.2025 20:43:18
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can...
CVE-2024-55947
- EPSS 75.2%
- Veröffentlicht 23.12.2024 16:15:07
- Zuletzt bearbeitet 10.04.2025 14:47:42
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
CVE-2024-54148
- EPSS 0.84%
- Veröffentlicht 23.12.2024 16:15:07
- Zuletzt bearbeitet 10.04.2025 14:48:03
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
CVE-2024-44625
- EPSS 14.95%
- Veröffentlicht 15.11.2024 17:15:20
- Zuletzt bearbeitet 21.11.2024 09:36:48
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
CVE-2022-1884
- EPSS 1.77%
- Veröffentlicht 15.11.2024 11:15:07
- Zuletzt bearbeitet 19.11.2024 14:47:48
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.gi...
CVE-2024-39933
- EPSS 0.69%
- Veröffentlicht 04.07.2024 16:15:02
- Zuletzt bearbeitet 10.04.2025 13:45:38
Gogs through 0.13.0 allows argument injection during the tagging of a new release.
CVE-2024-39932
- EPSS 17.18%
- Veröffentlicht 04.07.2024 16:15:02
- Zuletzt bearbeitet 10.04.2025 13:44:52
Gogs through 0.13.0 allows argument injection during the previewing of changes.
CVE-2024-39931
- EPSS 50.7%
- Veröffentlicht 04.07.2024 16:15:02
- Zuletzt bearbeitet 10.04.2025 13:43:51
Gogs through 0.13.0 allows deletion of internal files.